Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | Link all plugins to libstrongswan. | Tobias Brunner | 2010-02-25 | 56 | -15/+56 | |
| | ||||||
* | Avoid a race condition that could lead to a segmentation fault. | Tobias Brunner | 2010-02-25 | 1 | -3/+7 | |
| | | | | | | | | | | | | Let's assume the callback function of a callback job returns JOB_REQUEUE_FAIR in one call and JOB_REQUEUE_NONE in the next. Before this fix, the thread executing the callback job would requeue the job before unregistering itself. If there was a context switch right after the job got requeued, and if the thread that requeued the job never got resumed until a second thread executed the job and, due to the return value of JOB_REQUEUE_NONE, destroyed it, then when the first thread eventually got resumed and tried to lock the mutex to unregister itself the pointer wouldn't be valid anymore, thus resulting in a segmentation fault. | |||||
* | Use side-channel secured mpz_powm_sec of libgmp 5, if available | Martin Willi | 2010-02-18 | 3 | -0/+14 | |
| | ||||||
* | Updated debian package for NetworkManager-strongswan-1.1.2 | Martin Willi | 2010-02-18 | 1 | -0/+7 | |
| | ||||||
* | Version bump and NEWS for NetworkManager-strongswan-1.1.2 release | Martin Willi | 2010-02-18 | 2 | -1/+8 | |
| | ||||||
* | Updated german translation | Martin Willi | 2010-02-18 | 1 | -57/+104 | |
| | ||||||
* | Tooltips are translatable | Martin Willi | 2010-02-18 | 1 | -9/+9 | |
| | ||||||
* | Newer glade requires explicit vertical vboxes | Martin Willi | 2010-02-18 | 1 | -0/+5 | |
| | ||||||
* | Fixed lost renaimings in android plugin | Martin Willi | 2010-02-18 | 1 | -13/+14 | |
| | ||||||
* | Added Android plugin, currently provides DNS handling on Android | Martin Willi | 2010-02-17 | 6 | -0/+405 | |
| | ||||||
* | Invoke missing message() hook for incoming responses | Martin Willi | 2010-02-17 | 1 | -0/+1 | |
| | ||||||
* | Detect windows hosts to add specific workarounds. | Tobias Brunner | 2010-02-12 | 2 | -0/+7 | |
| | ||||||
* | Adding support for AES GMAC (RFC4543). | Tobias Brunner | 2010-02-12 | 14 | -103/+124 | |
| | ||||||
* | Do not build own authentication data before we've verified others, we need ↵4.3.6 | Martin Willi | 2010-02-09 | 1 | -28/+33 | |
| | | | | the other identity in EAP | |||||
* | Increased the buffer for netlink responses. | Tobias Brunner | 2010-02-05 | 1 | -0/+1 | |
| | | | | | | | | If an error occurs while manipulating policies in the kernel, the original netlink request gets attached to the response. Prior to Linux 2.6.32 the size in the netlink header of the response was wrong. | |||||
* | initialize variables to avoid compiler warning | Andreas Steffen | 2010-02-05 | 1 | -2/+2 | |
| | ||||||
* | Use destination address of ppp interfaces as nexthop in starters default ↵ | Martin Willi | 2010-02-05 | 1 | -6/+25 | |
| | | | | route lookup | |||||
* | init_fetch() changed to fetch_initialize() | Andreas Steffen | 2010-02-05 | 1 | -1/+1 | |
| | ||||||
* | Use child_updown hook in updown plugin, fixes doubled invocation of down script | Martin Willi | 2010-02-03 | 1 | -47/+17 | |
| | ||||||
* | renamed init_fetch() to fetch_initialize() | Andreas Steffen | 2010-02-02 | 2 | -2/+2 | |
| | ||||||
* | Some whitespace and code cleanups concerning the mediation extension. | Tobias Brunner | 2010-02-02 | 3 | -12/+10 | |
| | ||||||
* | Join pluto's fetching thread instead of detaching it in order to avoid that ↵ | Tobias Brunner | 2010-02-02 | 3 | -6/+26 | |
| | | | | the leak-detective reports a memleak. | |||||
* | corrected captions | Andreas Steffen | 2010-02-01 | 1 | -2/+2 | |
| | ||||||
* | warn if loaded local certificate is invalid | Andreas Steffen | 2010-02-01 | 1 | -3/+5 | |
| | ||||||
* | Added a ipsec.conf "inactivity" option to configure inactivity timeout for ↵ | Martin Willi | 2010-01-27 | 9 | -27/+39 | |
| | | | | CHILD_SAs | |||||
* | Made inactivity_timeout a per CHILD_SA config option | Martin Willi | 2010-01-27 | 9 | -16/+41 | |
| | ||||||
* | Refactored EAP payload, avoid unaligned word access | Martin Willi | 2010-01-21 | 1 | -103/+68 | |
| | ||||||
* | Added a METHOD2() macro that implements a method for two different interfaces | Martin Willi | 2010-01-21 | 1 | -1/+11 | |
| | ||||||
* | Support RADIUS messages up to 4096 bytes, RADIUS EAP-Message fragmentation | Martin Willi | 2010-01-19 | 3 | -9/+22 | |
| | ||||||
* | Support TLS client authentication Extended Key Usage in x509 generation | Martin Willi | 2010-01-14 | 6 | -21/+38 | |
| | ||||||
* | Block the signals before the call to sigwait. | Tobias Brunner | 2010-01-12 | 1 | -0/+1 | |
| | ||||||
* | Support for closing CHILD/IKE_SA if a CHILD_SA is inactive. | Martin Willi | 2010-01-12 | 4 | -0/+229 | |
| | ||||||
* | Added strongswan.conf options to configure retransmission timeouts | Martin Willi | 2010-01-11 | 2 | -5/+28 | |
| | ||||||
* | Added a "double" getter to libstrongswan settings | Martin Willi | 2010-01-11 | 2 | -0/+35 | |
| | ||||||
* | Cast unaligned memcpy() args to char*, avoids over-optimization on ARM | Martin Willi | 2010-01-11 | 1 | -4/+10 | |
| | | | | See http://infocenter.arm.com/help/index.jsp?topic=/com.arm.doc.faqs/ka3934.html | |||||
* | log EAP-only authentication proposal | Andreas Steffen | 2010-01-11 | 1 | -3/+5 | |
| | ||||||
* | pluto and charon are using the same strongSwan Vendor ID | Andreas Steffen | 2010-01-11 | 1 | -1/+1 | |
| | ||||||
* | EAP-MSCHAPv2 is indeed mutual, but is prone to MITM dictionary attacks | Martin Willi | 2010-01-07 | 1 | -1/+1 | |
| | ||||||
* | Support EAP-only authentication for mutual and key deriving EAP methods | Martin Willi | 2010-01-07 | 5 | -31/+96 | |
| | ||||||
* | Indicate and dected support for EAP-only authentication | Martin Willi | 2010-01-07 | 2 | -7/+28 | |
| | ||||||
* | Match to private use algorithms only if we know we are talking to strongSwan | Martin Willi | 2010-01-07 | 8 | -22/+41 | |
| | ||||||
* | Interpret private use BEET mode notify only if we know we are talking to ↵ | Martin Willi | 2010-01-07 | 1 | -1/+9 | |
| | | | | strongSwan | |||||
* | Add an option to send a vendor ID, allows us to properly support private ↵ | Martin Willi | 2010-01-07 | 9 | -8/+205 | |
| | | | | extensions | |||||
* | added some recent new attributes registered with IANA | Andreas Steffen | 2010-01-07 | 2 | -3/+9 | |
| | ||||||
* | ipsec pki --self|issue supports --pathlen option setting a path length ↵ | Andreas Steffen | 2009-12-31 | 5 | -5/+35 | |
| | | | | constraint | |||||
* | make error message about missing MD4 hasher more explicit | Andreas Steffen | 2009-12-30 | 1 | -1/+1 | |
| | ||||||
* | differentiate EAP method initialization errors | Andreas Steffen | 2009-12-30 | 1 | -12/+18 | |
| | ||||||
* | Pluto's fetcher thread is now created via libstrongswan. | Tobias Brunner | 2009-12-26 | 1 | -4/+11 | |
| | ||||||
* | enforce RFC 3779 address constraints on traffic selectors | Andreas Steffen | 2009-12-25 | 1 | -0/+61 | |
| | ||||||
* | Adapted the load_tester kernel-interface to the changes introduced in 6ec949e02. | Tobias Brunner | 2009-12-23 | 1 | -2/+3 | |
| |